Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.
2021-06-29T21:15:07.880
2024-11-21T06:12:47.760
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | westerndigital | wd_my_book_live_firmware | ≥ 2.0 | Yes |
Hardware | westerndigital | wd_my_book_live | - | No |
Operating System | westerndigital | wd_my_book_live_duo_firmware | * | Yes |
Hardware | westerndigital | wd_my_book_live_duo | - | No |